tkgthn[.]cfhostname11[.]cloud
Zusammenfassung der Beweislage
PhishDestroy identifies tkgthn.cfhostname11.cloud as an active phishing domain that was registered on June 12, 2025 through Gname.com Pte. Ltd. and currently resolves to IP 104.18.14.115. VirusTotal shows zero detections across 95 scanning engines, indicating the page is still under the radar. The domain was flagged for hosting a generic phishing page designed to harvest user credentials under an unverified SSL certificate issued by Google Trust Services. No specific brand impersonation or drainer kit artifacts are present in the available telemetry.
Technical indicators confirm the domain’s recent creation (June 12 2025), a VirusTotal score of 1/95 detections, registration via Gname.com Pte. Ltd, resolution to IP 104.18.14.115, and issuance of an SSL certificate by Google Trust Services. Google Safe Browsing (GSB) has not yet blacklisted the domain, and no blocklist hits were recorded at the time of analysis. The domain’s age and lack of detections suggest it may be part of a newly deployed campaign still gaining traction.
The domain remains active and poses a moderate but evolving risk due to its low detection footprint and active SSL certificate. Immediate actions include adding the domain and its resolving IP to blocklists, flagging the SSL certificate for revocation, and updating network defense rules to block inbound and outbound traffic. Users should avoid interacting with the domain and report any sightings via their organization’s incident response channels. Remaining risk is classified as under_investigation due to the lack of historical telemetry and the potential for additional payloads to be introduced. Security teams are advised to monitor for lateral movement and credential theft patterns associated with this domain.
Momentaufnahme der übermittelten Beweise
- Gesendet
- Protokolleinträge
- 1
- Fall-ID
PD-20260324-AF58C4- Titel der erfassten Seite
- tkgthn.cfhostname11.cloud/
- PDF-Artefakt
- PDF-Beweis
Vollständiger Beweistext
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
ICANN OVERSIGHT
Registration: cfhostname11.cloud
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For the registrable domain cfhostname11.cloud behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of tkgthn.cfhostname11.cloud · checked Mar 24, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt